CVE-2025-9613

A vulnerability was discovered in the PCI Express (PCIe) Integrity and Data Encryption (IDE) specification, where insufficient guidance on tag reuse after completion timeouts may allow multiple outstanding Non-Posted Requests to share the same tag. This tag aliasing condition can result in completions being delivered to the wrong security context, potentially compromising data integrity and confidentiality.
Configurations

Configuration 1 (hide)

cpe:2.3:a:pcisig:pci_express_integrity_and_data_encryption:-:*:*:*:*:*:*:*

History

14 Jan 2026, 17:43

Type Values Removed Values Added
References () https://pcisig.com/PCIeIDEStandardVulnerabilities - () https://pcisig.com/PCIeIDEStandardVulnerabilities - Vendor Advisory
References () https://pcisig.com/specifications - () https://pcisig.com/specifications - Product
CPE cpe:2.3:a:pcisig:pci_express_integrity_and_data_encryption:-:*:*:*:*:*:*:*
First Time Pcisig
Pcisig pci Express Integrity And Data Encryption
CWE NVD-CWE-noinfo

10 Dec 2025, 17:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5

09 Dec 2025, 20:15

Type Values Removed Values Added
References
  • () https://pcisig.com/PCIeIDEStandardVulnerabilities -

09 Dec 2025, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-09 19:15

Updated : 2026-01-14 17:43


NVD link : CVE-2025-9613

Mitre link : CVE-2025-9613

CVE.ORG link : CVE-2025-9613


JSON object : View

Products Affected

pcisig

  • pci_express_integrity_and_data_encryption